Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-40264LowOpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
CVE-2026-39388Low· 3.1OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-39946Medium· 4.9OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBao's SQL Injection in PostgreSQL database secrets engine
CVE-2026-40890High· 7.5github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…
CVE-2026-28684Medium· 6.6python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
CVE-2026-35588Medium· 6.3Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
CVE-2026-34839Medium· 6.5Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVE-2026-35587High· 8.8Glances has SSRF in IP Plugin via public_api leading to credential leakage
Glances has SSRF in IP Plugin via public_api leading to credential leakage
CVE-2026-39378Medium· 6.5nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
CVE-2026-33626High· 7.5PoCLMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2026-39377Medium· 6.5nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
CVE-2026-6634Medium· 6.3Memos has an Incorrect Privilege Assignment issue
Memos has an Incorrect Privilege Assignment issue
MAL-2026-2958NoneMalicious code in mysten_metrics (crates.io)
Malicious code in mysten_metrics (crates.io)
CVE-2026-6596High· 7.3Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
CVE-2026-6599Medium· 6.3Langflow vulnerable to injection
Langflow vulnerable to injection
CVE-2025-66335Medium· 5.3Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
CVE-2026-6608Medium· 5.3FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6606High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6603High· 7.3AgentScope Vulnerable to Remote Code Injection
AgentScope Vulnerable to Remote Code Injection
CVE-2026-6598Medium· 4.3Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6605High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6604High· 7.3AgentScope vulnerable to Server-Side Request Forgery
AgentScope vulnerable to Server-Side Request Forgery
CVE-2026-6597Low· 2.7Langflow has an Information Leak through Incomplete API Key Redaction
Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-6607Medium· 5.3FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
CVE-2026-3219Mediumpip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
MAL-2026-2947NoneMalicious code in moonbit-schema-utils (PyPI)
Malicious code in moonbit-schema-utils (PyPI)
MAL-2026-2946NoneMalicious code in moonbit-metrics-validator (PyPI)
Malicious code in moonbit-metrics-validator (PyPI)
MAL-2026-2945NoneMalicious code in moonbit-locale-compat (PyPI)
Malicious code in moonbit-locale-compat (PyPI)
CVE-2026-32690Low· 3.7Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false